ENTRY № 34 · STATUTORY READING · CFPB · ECOA REG B
PUBLISHED 2026-05-11 · ~11-MIN READ · WARRANT COMPLIANCE

CFPB AI guidance, line by line.

The Consumer Financial Protection Bureau never passed a dedicated AI statute. It read the existing statutes back over the algorithm instead, in a stack of circulars — and then on 12 May 2025 it withdrew almost the whole stack in one Federal Register notice. Circulars 2022-03, 2022-04 and 2024-06 are all on the withdrawal list. This page has been corrected to say so. The part that matters is what did not change: ECOA Regulation B still requires specific principal reasons for an adverse action, and 12 CFR 1002.9(b)(2) still names a model score as insufficient. Penalty exposure under 12 U.S.C. 5565 reaches USD 1,000,000 per day for knowing violations of Federal consumer financial law.

Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant.

REGULATOR
CFPB
Consumer Financial Protection Bureau. Created by Dodd-Frank Title X (2010), codified at 12 U.S.C. 5491.
OPERATIVE RULE
12 CFR 1002.9· Reg B
Specific principal reasons for adverse action. Unaffected by the 12 May 2025 withdrawal. Circulars 2022-03, 2022-04 and 2024-06 were all withdrawn at 90 FR 20084.
PENALTY
USD 1M/day
Per 12 U.S.C. 5565 third-tier civil penalty for knowing violations. Plus consumer restitution.
01 · THE CFPB STACK

The Bureau, its statutory authority.

The Consumer Financial Protection Bureau was created by the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010, Title X, codified at 12 U.S.C. 5491. The statutory grant is broad. The Bureau regulates the offering and provision of consumer financial products and services under the Federal consumer financial laws, an enumerated list at 12 U.S.C. 5481(14) that includes the Equal Credit Opportunity Act, the Fair Credit Reporting Act, the Truth in Lending Act, the Real Estate Settlement Procedures Act, and the Consumer Financial Protection Act itself.

The Bureau has four operative levers. Rulemaking under 12 U.S.C. 5512. Supervision of covered persons under 12 U.S.C. 5514 and 5515. Enforcement under 12 U.S.C. 5564. And interpretive guidance via consumer financial protection circulars, supervisory highlights, and advisory opinions. The AI stack the Bureau has built since 2022 runs almost entirely on the fourth lever.

Circulars are not rules. The Bureau styles them as policy statements that articulate the Bureau's interpretation of how existing law applies. They impose no new obligations and require no notice-and-comment — which is exactly why the Bureau could withdraw sixteen of them in a single notice on 12 May 2025 without touching a regulation. The exposure was already there. The circular told you where it sat. Now it does not, and you read the regulation yourself.

Accordingly, the Bureau is hereby withdrawing all of the guidance materials set forth in section III below. [...] the Bureau does not intend to prioritize the enforcement of such guidance against parties that do not conform to the guidance during the pendency of any withdrawal. Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal · 90 FR 20084 · 12 May 2025 · withdrawals applicable as of 12 May 2025

Read the second sentence carefully, because it is narrower than a repeal. The Bureau deprioritised enforcement of the guidance. It did not and could not deprioritise ECOA, FCRA, or the statutory prohibition on unfair, deceptive, or abusive acts. The notice says plainly that "such withdrawal is not necessarily final", so a reissued circular is a live possibility. And a state attorney general enforcing Federal consumer financial law under 12 U.S.C. 5552 is not bound by the Bureau's enforcement priorities at all.

"Companies are not absolved of their legal responsibilities when they let a black-box model make lending decisions."Rohit Chopra · CFPB Director · 2022-05-26

So the perimeter as of July 2026 is shorter than it was, and the distinction that survives is between regulations and guidance. What still binds: ECOA and Regulation B at 12 CFR 1002.9; the FCRA duties on users of consumer reports; the statutory prohibition at 12 U.S.C. 5531 and 5536; and the interagency Quality Control Standards for Automated Valuation Models final rule, a notice-and-comment rule published at 89 FR 64538 on 7 August 2024 and effective 1 October 2025, which the guidance withdrawal did not reach. What is withdrawn: Circular 2022-03 on adverse-action notices and complex algorithms (87 FR 35864); Circular 2022-04 on data security (87 FR 54346); Circular 2024-06 on background dossiers and algorithmic scores (89 FR 88875). Each appears by name and Federal Register citation in the withdrawal notice at 90 FR 20084.

Penalty exposure runs through 12 U.S.C. 5565. The three-tier structure is the operative ceiling. Five thousand dollars per day for any violation of Federal consumer financial law. Twenty-five thousand per day for reckless violations. One million per day for knowing violations. The amounts are adjusted annually for inflation under 28 U.S.C. 2461. Each day a noncompliant AI system processes a covered transaction is a separate violation.

02 · 12 CFR 1002.9 · THE RULE THAT SURVIVED

ECOA adverse-action notices when AI is used.

The statement of reasons for adverse action required by paragraph (a)(2)(i) of this section must be specific and indicate the principal reason(s) for the adverse action. Statements that the adverse action was based on the creditor's internal standards or policies or that the applicant, joint applicant, or similar party failed to achieve a qualifying score on the creditor's credit scoring system are insufficient. 12 CFR 1002.9(b)(2) · Regulation B · eCFR title 12 as at 1 July 2026

Start here rather than with a circular, because this is the text that binds and it is untouched by the 2025 withdrawal. Two failure patterns are named in the rule itself, not in commentary: the creditor's internal standards, and a failed qualifying score. The second one is the whole AI problem in six words. A model that emits a probability and nothing else emits precisely the thing Regulation B calls insufficient.

The withdrawn Circular 2022-03 said out loud what the regulation implies — that a creditor cannot justify noncompliance on the ground that its technology is too complicated or opaque to understand. That was a useful sentence and it is no longer the Bureau's stated position. Nothing turns on losing it. The regulation never contained an opacity carve-out to begin with, so removing the interpretation that said so leaves the creditor in the same place: it must produce specific principal reasons, and the architecture of the model is the creditor's problem to solve, not the applicant's to absorb.

What follows for the engineering is unchanged, and it is worth stating without reference to any guidance document. The creditor records, per decision, the input feature vector at the level of the named variables. It records the output score or class. It records the principal reasons in plain language. The reasons are not generated retroactively. They are persisted at the moment the decision is made, in the same trace as the decision. A reason that names a variable category — length of credit history, debt-to-income ratio, recency of a derogatory item — and the direction of its effect is what satisfies "specific and indicate the principal reason(s)". If the model cannot yield that, the model is not deployable in adverse-action territory, and that conclusion comes from 1002.9(b)(2), not from a circular that has since been pulled.

A common failure pattern. The creditor uses an LLM-based agent to summarise an application package and produce a recommendation. The LLM returns natural-language output. The downstream rules engine converts the output to an approve, deny, or refer-to-human disposition. The audit trail records the LLM output. It does not record the principal-reason extraction. When the regulator asks how reason A versus reason B was selected on a given denied application, the answer must trace back to the recorded LLM context, not to a separate post-hoc reason model that was not in the decision path.

03 · 2023 CHATBOT SPOTLIGHT

Chatbots and UDAAP exposure.

Customers turn to their financial institutions for assistance with financial products and services and rightfully expect to receive timely, straightforward answers, regardless of the processes or technologies used. […] Risk of diminished customer service and trust when chatbots reduce access to individualized human support agents. CFPB Issue Spotlight, "Chatbots in consumer finance", June 2023 (released 6 June 2023) — § 1 Executive Summary, quoted verbatim with the elision marked. Retrieved 6 Aug 2026.

The June 2023 issue spotlight is not a circular and not a rule, and it is careful to say so. Its footnote 3 reads: "This issue spotlight is not intended to impose any obligations or define any rights and is not intended as a CFPB interpretation of any regulation or statute." So it cannot be cited as the Bureau's reading of UDAAP, and this page does not cite it that way. Structurally the document names three areas of interest, not four: § 3.1 "Limited ability to solve complex problems", § 3.2 "Hindering access to timely human intervention", and § 3.3 "Technical limitations and associated security risks", followed by § 4 "Risks associated with the integration of deficient chatbots". The four-way breakdown below is Warrant's operational mapping of those areas onto the statutes and rules that do impose obligations — the statutory routes are ours, not the Bureau's.

RISK 01
Deficient pathways to human support. Chatbots that cannot escalate, that loop, or that bury the human channel. STATUTORY ROUTE · UDAAP under 12 U.S.C. 5536. Failure to provide a meaningful path to dispute resolution is a potential unfair practice.
RISK 02
Inaccurate, incomplete, or fabricated responses. The Bureau names hallucinations and the consequences of providing wrong information about an account, a fee, or a regulatory right. STATUTORY ROUTE · UDAAP deceptive prong. A representation that is likely to mislead a reasonable consumer is a deceptive act regardless of intent.
RISK 03
Mishandling of complaints and disputes. Chatbots that route a Reg E error claim or a Reg Z billing-error notice into a dead end. Warrant's addition — the phrase "complaints and disputes" does not appear in the spotlight; the exposure comes from the rules cited below, which stand on their own. STATUTORY ROUTE · Reg E 12 CFR 1005.11 and Reg Z 12 CFR 1026.13 have specific timelines. Failure to honour them through a chatbot channel does not extinguish the obligation.
RISK 04
Privacy and security gaps. Disclosure of sensitive information to the wrong session, persistence of conversation logs without retention controls. STATUTORY ROUTE · the GLBA Safeguards Rule, plus the statutory prohibition at 12 U.S.C. 5531 and 5536. The Bureau's data-security reading in Circular 2022-04 was withdrawn on 12 May 2025; the statute it read was not.

The supervisory implication is that a deployed financial-services chatbot is not outside the four perimeters above merely because the institution did not build the model. A bank using a third-party LLM for a customer-facing channel is the covered person for UDAAP purposes. What the spotlight actually says on liability is narrower and worth quoting rather than paraphrasing: "Like the processes they replace, chatbots must comply with all applicable federal consumer financial laws, and entities may be liable for violating those laws when they fail to do so." Treating a hallucinated answer as a deceptive practice the institution disseminated is Warrant's reading of 12 U.S.C. 5531 and 5536, not a position the Bureau has stated — the spotlight disclaims being an interpretation of any statute.

The operative engineering pattern for a defensible chatbot deployment has four parts. A factuality check on every customer-facing response, recorded in the trace. A typed escalation event whenever a session crosses a defined complexity or topic boundary. An immutable record of every complaint or dispute initiated through the channel, time-stamped and routed to the same queue as written complaints. A privacy-disclosure record per session covering what the chatbot was told and what it disclosed.

04 · LEP ACCOMMODATIONS

Limited English Proficiency and AI.

An earlier version of this page said it could not determine whether the Bureau's January 2021 LEP statement survived the 12 May 2025 withdrawal. That is now resolved, against the notice itself. The statement is the Statement Regarding the Provision of Financial Products and Services to Consumers With Limited English Proficiency, 86 FR 6306, published 21 January 2021. It does not appear anywhere in the withdrawal notice at 90 FR 20084: the notice's Policy Statements list runs to eight items and does not include it, and the strings "limited English", "language" and "6306" occur zero times in the notice's full text. So it was not withdrawn by that notice. One caveat the notice supplies itself: the Bureau said it "intends to continue reviewing all guidance documents to determine whether they should ultimately be retained", so this is a status as at 6 August 2026, not a permanent one.

What the statement implies for an AI agent is direct, though note it is a policy statement rather than a rule. If the institution markets a product to LEP consumers in a non-English language, the digital channel should honour the same language commitments as the human channel. An LLM-based chatbot that operates in English by default but is offered to Spanish-speaking customers must either provide a substantively equivalent Spanish experience or be explicitly scoped out of Spanish-language consumer engagement. The underlying exposure does not depend on the statement at all: a consumer-facing agent that answers less accurately in one language than another is exposed under ECOA on the credit path and under 12 U.S.C. 5531 and 5536 on the communications path.

On translation quality, the reading below is Warrant's and is marked as such rather than attributed to the Bureau. A machine-translated disclosure that materially alters the meaning of a Reg Z right or a Reg DD term sheet is a candidate deceptive act under 12 U.S.C. 5536 on the same analysis that applies to any other misdescription of a term. The institution does not get a defence on the basis that the LLM produced the translation. The institution is the discloser.

The operative engineering pattern. Record the language of every consumer interaction in the trace. Record the source language of every disclosure rendered to the consumer and any translation step applied. Record the human or model that produced the translation. Record, where applicable, the back-translation verification step.

05 · AVM COLLATERAL RULE

Automated valuation models and nondiscrimination.

The agencies are issuing a final rule to implement the quality control standards mandated by the Dodd-Frank Wall Street Reform and Consumer Protection Act for the use of automated valuation models by mortgage originators and secondary market issuers in determining the collateral worth of a mortgage secured by a consumer's principal dwelling. Federal Register · 89 FR 64538 · published 7 August 2024 · effective 1 October 2025

This is the only AI-specific final rule on the CFPB stack as of May 2026, and the CFPB is one of six issuing agencies. The Federal Reserve Board, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, the National Credit Union Administration, the Federal Housing Finance Agency, and the CFPB jointly adopted the rule under the authority of section 1125 of the Financial Institutions Reform, Recovery, and Enforcement Act, added by Dodd-Frank section 1473(q).

The rule imposes five quality-control standards on any institution that uses an AVM in connection with making a credit decision or covered securitisation determination secured by a consumer's principal dwelling. Confidence in the estimates produced. Protection against data manipulation. Avoidance of conflicts of interest. Random sample testing and reviews. And compliance with applicable nondiscrimination laws.

The fifth standard is the AI-specific one. The Bureau and its sister agencies were explicit that AVMs trained on historical valuation data risk replicating historical discrimination in property valuation. The rule does not specify a particular fairness test. It requires the institution to have policies, practices, procedures, and control systems that are designed to ensure the AVM complies with nondiscrimination laws. The Fair Housing Act, the Equal Credit Opportunity Act, and the disparate-impact doctrine in Texas Department of Housing v. Inclusive Communities apply.

The operative engineering pattern for an AVM deployment after 1 October 2025. Record, per valuation, the AVM model identifier and version. Record the input feature set and the geographic context. Record the output and any human override. Record, on a periodic basis, the disparate-impact testing results, the corrective actions taken, and the documentation of nondiscrimination compliance reviews. The record is the institution's defence in any fair-lending examination.

06 · 2024-2025 STATEMENTS

2024 and 2025 statements on AI in lending.

The Bureau supplemented the 2022-2023 guidance in 2024 and then withdrew the supplement. Circular 2024-06 on background dossiers and algorithmic scores in hiring, promotion, and other employment decisions was published at 89 FR 88875 on 12 November 2024 and appears as item 1 on the withdrawal list at 90 FR 20084. Its reasoning is worth knowing and is no longer citable as the Bureau's position: a score from a third-party algorithm used in an employment adverse action is a consumer report under the FCRA, and the user carries notice and accuracy obligations. Those FCRA obligations come from the statute and remain in force. The circular that mapped them onto algorithmic scores does not.

The Bureau has also issued statements on AI in mortgage origination through its supervisory highlights and through the joint regulator statement on consumer-financial-services use of AI, signed by the CFPB, the FTC, the Department of Justice Civil Rights Division, and the Equal Employment Opportunity Commission on 25 April 2023 — the Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems. It is short and operative: "Existing legal authorities apply to the use of automated systems and innovative new technologies just as they apply to other practices." That statement is not on the 90 FR 20084 withdrawal list.

Warrant does not characterise the content of individual Supervisory Highlights findings on this page. An earlier version listed AI-driven account-closure practices, debt-collection scripts and third-party adverse-action notices as 2024–2025 findings; those specifics have been removed because they were not verified against a named, dated edition, and the honest form of the point does not need them. The durable observation stands on the instruments themselves: ECOA, FCRA and the UDAAP prohibition ask for the same artefacts they have always asked for, and the fact that an artefact was produced by an AI system is not a defence — it is a description of how the violation occurred.

07 · CROSS-REFERENCE WEB

CFPB, the Fair Housing Act, and the UDAAP perimeter.

The CFPB's AI guidance does not operate in isolation. Three other statutory perimeters attach to the same fact pattern. The Fair Housing Act, 42 U.S.C. 3601 and following, prohibits discrimination in residential real-estate transactions. ECOA, codified at 15 U.S.C. 1691 and implemented in Regulation B at 12 CFR Part 1002, prohibits discrimination in any aspect of a credit transaction. UDAAP, codified at 12 U.S.C. 5531 and 5536, prohibits unfair, deceptive, or abusive acts and practices.

The cross-reference web matters because the same AI deployment routinely touches all three. An AI mortgage-underwriting agent is subject to ECOA on the credit decision, the Fair Housing Act on the housing element, and UDAAP on every customer-facing communication. A finding under one statute does not preclude findings under the other two. The Department of Justice and HUD enforce the Fair Housing Act in parallel. State attorneys general enforce ECOA and UDAAP under 12 U.S.C. 5552.

The argument that AI opacity is a defence does not survive any of the three perimeters. Regulation B forecloses it at 12 CFR 1002.9(b)(2), which requires specific principal reasons and names a failed qualifying score as insufficient — no guidance document is needed to reach that. The Fair Housing Act's disparate-impact doctrine, affirmed by the Supreme Court in Texas Department of Housing v. Inclusive Communities Project (2015), does not require proof of intent; it requires proof that a facially neutral practice has a disproportionate adverse effect, and an opaque model cannot rebut the showing. UDAAP requires no scienter for the unfair or deceptive prongs.

The same chain runs through state actors, and the safest way to say so is without a roster. Several states have layered automated-decision-system or AI rules over the Federal floor, and the detail — which statute, which effective date, which sections — moves fast enough that Warrant states it only where it has checked the enacted instrument. For a New York-regulated institution the concrete overlay is 23 NYCRR Part 500, read at the Part 500 mapping. The Federal floor is not a ceiling, but a claim about any particular state's rule belongs on a page where that state's instrument has been read.

08 · FIELD MAPPING

Where Warrant maps CFPB obligations.

The mapping below is by-action, not by-trace, because each obligation attaches at the decision moment, not at the session moment. Read the FIELD column literally: it names properties of the signed warrant-v1 package as defined in api/spec/warrant-v1-evidence.schema.json, which sets additionalProperties: false at the root and on every action and authorization row — so a name absent from the schema is prohibited, not merely unimplemented. Four of the five rows below have no field. Consumer-protection law asks for artefacts the institution produces: an adverse-action notice, an accuracy control on customer-facing output, a language-access decision, a valuation-model quality-control record. Warrant evidences the decision those artefacts are owed for; it does not carry the artefacts, and only the per-decision rationale row maps to a field that exists.

REG B
12 CFR 1002.9(a)(2)(i) · statement of specific reasons for the action taken. OBLIGATION · per-decision reasons trail · FIELD · none. warrant-v1 has no adverse-action-reasons field; the statement of specific reasons is the creditor's notice, and no property of the package holds its text. What the package carries for this row is obligations.<action_id>[].id with .compliance and .evidence — whether the reasons obligation was met for that action, and the assessment that reached it.
1002.9(b)(2)
A failed qualifying score is insufficient as a reason, so the opacity defence never had a home in the rule. OBLIGATION · per-decision rationale not derivable post-hoc · FIELD · authorizations[].justification, one row per action_id. Stated precisely, because the distinction is the whole point of the rule: the decision-time rationale is whatever the ingested trace's own step outputs recorded, and authorizations[].justification is Warrant's assessment of that action, produced at attestation. The package binds the two together; it does not manufacture a contemporaneous reason where the trace carried none.
UDAAP
12 U.S.C. 5531 · chatbot accuracy under the deceptive prong. OBLIGATION · hallucination check trail · FIELD · none. warrant-v1 has no factuality field — no checker, no score, no threshold — so a chatbot's accuracy is not something the package attests. What it does carry per action is authorizations[].justification and .confidence, which record Warrant's own confidence in its authorization judgement, not the agent's truthfulness.
LEP
CFPB 2021 LEP statement · substantively equivalent non-English experience. OBLIGATION · language-of-decision recorded · FIELD · none. warrant-v1 has no language field, and it has no metadata root at all — the root property list is closed, so a metadata.* path can never appear on a package. classification.jurisdictions records where the decision sits, which is not the language it was delivered in.
AVM
12 CFR Part 34 et al. (AVM final rule) · nondiscrimination quality control. OBLIGATION · per-valuation model identification plus periodic disparate-impact record · FIELD · none. warrant-v1 identifies no deployer model and holds no disparate-impact review; the periodic record is an institutional artefact, not a per-decision one. The receipt's pipeline_models names the models Warrant's own assessment pipeline ran, which is a different thing and should not be read as the valuation model under review.
W
Sample US lending evidence package · Warrant registerINDEPENDENTLY VERIFIABLE
→ /v/7de85ceaeac42a47
09 · FAQ

Questions a compliance officer asks first.

Is Circular 2022-03 still in effect?

No. The Bureau withdrew it, with Circulars 2022-04 and 2024-06 and most of its other guidance, at 90 FR 20084 on 12 May 2025, in a notice titled Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal. The notice states that the withdrawals are applicable as of 12 May 2025 and that the Bureau does not intend to prioritise enforcement of the withdrawn guidance during the pendency of any withdrawal. It also says the withdrawal is "not necessarily final". None of that changes ECOA or Regulation B.

What counts as a specific principal reason under ECOA?

12 CFR 1002.9(b)(2) is the operative text, and it survived the withdrawal because it is a regulation: the statement of reasons "must be specific and indicate the principal reason(s) for the adverse action", and statements resting on the creditor's internal standards or on a failure "to achieve a qualifying score on the creditor's credit scoring system are insufficient". A reason that names a variable category — length of credit history, debt-to-income ratio, recency of a derogatory item — and the direction of its effect is the operative pattern.

Does the 2025 withdrawal reduce my exposure?

Not much, and not in the places that matter. The circulars never created the obligations; they described them. ECOA at 15 U.S.C. 1691(d), Regulation B at 12 CFR 1002.9, the FCRA duties, and the prohibition at 12 U.S.C. 5531 and 5536 are all untouched. Three things do change. The Bureau has said it will deprioritise enforcement of the withdrawn guidance while the withdrawal stands. Reissue is expressly possible. And a state attorney general enforcing Federal consumer financial law under 12 U.S.C. 5552 is not governed by the Bureau's enforcement priorities. A firm that built its adverse-action evidence to the withdrawn circular's standard should keep it there.

How does CFPB interact with FTC and state AGs on AI consumer protection?

CFPB has primary authority over Federal consumer financial law for covered persons under 12 U.S.C. 5481. FTC retains parallel UDAP authority over most non-bank actors under section 5 of the FTC Act. State attorneys general can enforce Federal consumer financial law against non-banks under 12 U.S.C. 5552 and their own state UDAP statutes. The 25 April 2023 joint statement signed by CFPB, FTC, DOJ Civil Rights, and EEOC formalises the four-way coordination on AI deployments.

What is the CFPB position on chatbot UDAAP risk?

The Bureau has not stated one, and its own document says so. The June 2023 issue spotlight "Chatbots in consumer finance" carries a footnote reading: "This issue spotlight is not intended to impose any obligations or define any rights and is not intended as a CFPB interpretation of any regulation or statute." It is a research report, not guidance. Structurally it names three areas of interest, not four — § 3.1 "Limited ability to solve complex problems", § 3.2 "Hindering access to timely human intervention", § 3.3 "Technical limitations and associated security risks". On liability it says only that "[l]ike the processes they replace, chatbots must comply with all applicable federal consumer financial laws, and entities may be liable for violating those laws when they fail to do so." Reading a hallucinated answer as a deceptive act under 12 U.S.C. 5531 and 5536 is Warrant's analysis, not a Bureau position.

Does CFPB action on AI affect non-banks, FinTech, and NBFI?

Yes. CFPB supervisory and enforcement authority under 12 U.S.C. 5514 reaches non-bank covered persons in residential mortgage, private education lending, payday lending, and any market the Bureau designates as larger participant. The 2022 invocation of dormant supervisory authority over non-bank entities posing a risk to consumers further broadened the perimeter. A FinTech lender is the same creditor for ECOA purposes as a national bank.

How does ECOA Regulation B specific-reasons requirement work for an LLM-based agent?

The agent must produce, at decision time, a recorded artifact that names the specific principal reasons for the adverse action in plain language. If the LLM is the operative scorer, the integrating creditor must extract reasons that name a variable and its effect, not the model architecture. A trace that records the prompt, the inputs, the output, and the post-hoc reason extraction is the operative evidence pattern. The reasons must be extractable from the same decision path as the disposition, not from a separate model run later.

10 · READ THE SOURCE

Read the source directly.

Authored by Warrant Compliance, the regulatory-analysis function at Warrant. [email protected]. Editorial commentary on regulatory text. Not legal advice. Corrected 28 July 2026. The verbatim quotation of 12 CFR 1002.9(b)(2) is taken from the eCFR rendering of title 12 as at 1 July 2026. The verbatim quotations of the withdrawal notice are taken from the Federal Register full text of 90 FR 20084, published 12 May 2025, in which Circular 2024-06 appears as item 1 (89 FR 88875), Circular 2022-04 as item 13 (87 FR 54346), and Circular 2022-03 as item 14 (87 FR 35864) of the Other Guidance list. The AVM final rule is 89 FR 64538 of 7 August 2024, effective 1 October 2025. An earlier version of this page presented the three withdrawn circulars as current authority and quoted 2022-03 in the present tense; that was wrong on the date and is corrected here.